Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hyper Backup Explorer HIGH 7.8
CVE-2022-49042

An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 …

Fix: 3.0.1-0156+
Fix from $1,950 2026-06-03
Note Station Client MEDIUM 5.9
CVE-2023-52951

A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers t…

Fix: 2.2.4-703+
Fix from $1,600 2026-06-03
Active Backup For Business Recovery Media Creator HIGH 7.8
CVE-2022-49036

An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Me…

Fix: 2.5.0-2081+
Fix from $1,950 2026-06-03
Active Backup For Business HIGH 8.6
CVE-2025-30028

A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.

Mitigation only
Fix from $1,950 2026-05-27
Active Backup For Business Agent MEDIUM 5.6
CVE-2025-66592

An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files w…

Fix: 3.1.0-4967+
Fix from $1,600 2026-05-27
Assistant MEDIUM 5.6
CVE-2025-66593

An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content…

Fix: 7.0.6-50085+
Fix from $1,600 2026-05-27
Storage Manager MEDIUM 5.5
CVE-2026-2237

A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 all…

Fix: 1.0.1-1100+
Fix from $1,600 2026-05-27
Beestation Os CRITICAL 9.8
CVE-2025-12686

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allo…

Fix: 1.3.2+
Fix from $2,300 2026-05-27
Diskstation Manager CRITICAL 9.8
CVE-2025-13392

Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-…

Fix: 7.2.2-72806-5+
Fix from $2,300 2026-05-27
C2 Identity Edge Server HIGH 7.5
CVE-2025-14713

An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers t…

Fix: 1.76.0-0307+
Fix from $1,950 2026-05-27
Safe Access MEDIUM 5.9
CVE-2025-10466

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.…

Fix: 1.3.1-0329+
Fix from $1,600 2026-05-27
Activeprotect Agent MEDIUM 5.6
CVE-2025-13593

Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted c…

Fix: 1.1.0-0439+
Fix from $1,600 2026-05-27
Contacts MEDIUM 5.4
CVE-2025-13167

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts befo…

Fix: 1.0.10-20659+
Fix from $1,600 2026-05-27
Beedrive MEDIUM 6.8
CVE-2024-11399

Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allow…

Fix: 1.3.2-13814+
Fix from $1,600 2026-05-27
Beedrive HIGH 7.8
CVE-2023-52945

Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to exe…

Fix: 1.3.2-13814+
Fix from $1,950 2026-05-27
Ssl Vpn Client HIGH 8.1
CVE-2021-47961

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user'…

Fix: 1.4.5-0684+
Fix from $1,950 2026-04-10
Ssl Vpn Client MEDIUM 6.5
CVE-2021-47960

A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access fi…

Fix: 1.4.5-0684+
Fix from $1,600 2026-04-10
Presto Client HIGH 7.3
CVE-2026-3091

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files and…

Fix: 2.1.3-0672+
Fix from $1,950 2026-02-24
Beedrive MEDIUM 5.6
CVE-2025-8074

Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary files wit…

Fix: 1.4.3-13973+
Fix from $1,600 2025-12-04
Beedrive HIGH 7.8
CVE-2025-54160

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.…

Fix: 1.4.2-13960+
Fix from $1,950 2025-12-04
Beedrive HIGH 7.5
CVE-2025-54159

Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files…

Fix: 1.4.2-13960+
Fix from $1,950 2025-12-04
Beedrive HIGH 7.8
CVE-2025-54158

Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to exec…

Fix: 1.4.2-13960+
Fix from $1,950 2025-12-04
Mail Server MEDIUM 6.3
CVE-2025-2848

A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical…

Fix: 1.7.6-10676 / 1.7.6-20676+
Fix from $1,600 2025-12-04
Router Manager HIGH 7.2
CVE-2025-29846

A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.

Fix: 1.3.1-9346+
Fix from $1,950 2025-12-04
Router Manager MEDIUM 5.4
CVE-2025-29843

A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.

Fix: 1.3.1-9346+
Fix from $1,600 2025-12-04
Diskstation Manager CRITICAL 9.6
CVE-2024-45538

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Sy…

Fix: 3.1.4-23079 / 7.2.1-69057-2+
Fix from $2,300 2025-12-04
Diskstation Manager HIGH 8.8
CVE-2024-5401

Improper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-42962-8 a…

Fix: 3.1.4-23079 / 7.2.1-69057-2+
Fix from $1,950 2025-12-04
Diskstation Manager HIGH 7.5
CVE-2024-45539

Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified C…

Fix: 3.1.4-23079 / 7.2.1-69057-2+
Fix from $1,950 2025-12-04
Router Manager MEDIUM 5.9
CVE-2024-53288

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Man…

Fix: 1.3.1-9346+
Fix from $1,600 2025-07-23
Router Manager HIGH 7.2
CVE-2024-53286

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Rou…

Fix: 1.3.1-9346+
Fix from $1,950 2025-07-23